Agent skill

Domains DNS

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and…

MITAuto-check passedDevOps & Cloud

Install Domains DNS

skills CLI
$ npx skills add ericrisco/rsc-harness --skill domains-dns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness domains-dns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/domains-dns .claude/skills/domains-dns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
domains-dns
GitHub stars
174
Token cost
~2.4k tokens
SKILL.md length
1,150 words
Files
7 (incl. scripts, references)
Skills in repo
233
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and…

  • Works in 4 steps: Name — does the domain exist and is it… → Delegation — do the registrar's… → Records — does the authoritative zone… → …
  • Pointing a domain at a host
  • SKILL.md covers Resolution order is debug order, Where the DNS lives, Apex vs www — the load-bearing… and Record cookbook (summary), plus 4 more sections
  • Runs Shell scripts from its folder; calls openssl and curl

What it does

Domains DNS is an agent skill from ericrisco/rsc-harness. Use when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and cutting nameservers over without downtime. NOT inbox placement or warmup (that is email-deliverability), NOT what runs behind the name (that is deployment).

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/record-cookbook.md`).

It sits in DevOps & Cloud, covering Cloud networking, Transactional email and Email management. It works with Cloudflare. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Pointing a domain at a host
  • Fixing broken HTTPS — delegating nameservers
  • Writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows
  • Standing up auto-renewing TLS

Example prompts

  • “/domains-dns”

Requirements

  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Name — does the domain exist and is it registered/not expired? (whois)
  2. Delegation — do the registrar's nameservers point at the DNS provider that actually holds the zone? (dig NS)
  3. Records — does the authoritative zone return the right A/AAAA/CNAME/ALIAS/MX/TXT/CAA? (dig @)
  4. TLS — does the served chain validate and is it unexpired? (openssl s_client)

What it can do on your machine

Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • openssl
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Domains DNS loads about 2.4k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 1,150 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,150 words, ~2,439 tokens.

Download SKILL.mdSave it as .claude/skills/domains-dns/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
domains-dns
description
Use when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and cutting nameservers over without downtime. NOT inbox placement or warmup (that is `email-deliverability`), NOT what runs behind the name (that is `deployment`).
tags
dns, tls, ssl, domains, https, acme, certbot, dig, caa, nameservers
recommends
email-deliverability, deployment, monitoring, cloudflare, vercel
origin
risco

Domains & DNS

You set up a name end to end: register or delegate it, write the records, and serve valid HTTPS. Almost every "my domain doesn't work" report is one of a handful of recurring mistakes. This skill names them and gives you paste-ready records plus the commands to prove they took.

Resolution order is debug order

A request resolves in one direction. Diagnose in the same direction, top-down, because the bug is almost always at the layer the user is not looking at.

  1. Name — does the domain exist and is it registered/not expired? (whois)
  2. Delegation — do the registrar's nameservers point at the DNS provider that actually holds the zone? (dig NS)
  3. Records — does the authoritative zone return the right A/AAAA/CNAME/ALIAS/MX/TXT/CAA? (dig @<authoritative-ns>)
  4. TLS — does the served chain validate and is it unexpired? (openssl s_client)

Rule: never debug TLS before you've confirmed the record resolves to the box you think it does — a cert error is often a record pointing at the wrong host. Query authoritative nameservers, not your laptop's cache, or you'll chase a stale answer for an hour.

Where the DNS lives

Pick one authoritative provider and keep the whole zone there. Splitting a zone across two providers (some records at the registrar, some at Cloudflare) is the source of "it works for me but not for them" — resolvers see whichever NS set answered.

Host the zone atChoose whenWhy
Registrar DNS (GoDaddy, Namecheap, Porkbull)Tiny static site, one or two recordsOne vendor, fewer logins; weak APIs and slow propagation
Dedicated DNS (Cloudflare, DNSimple)Most cases; want CNAME flattening + fast editsApex flattening, low TTL edits, good API; see ../cloudflare/SKILL.md
Cloud DNS (Route 53, Cloud DNS)Already all-in on AWS/GCP and want alias-to-LBNative alias records to cloud load balancers
Host-managed (Vercel, Netlify)The host is the only thing the domain servesAuto-TLS + apex flattening handled for you; see ../vercel/SKILL.md

Apex vs www — the load-bearing trap

You cannot put a CNAME at the zone apex (the naked example.com). The spec forbids a CNAME coexisting with the SOA and NS records that must live there (RFC 1034 §3.6.2, RFC 2181). Registrars that let you save it produce a silently broken zone.

text
# Bad — CNAME at the apex. Breaks SOA/NS; mail and other apex records vanish.
example.com.        CNAME   cname.vercel-dns.com.

# Good — flatten at the apex (ALIAS/ANAME or provider flattening), CNAME only on the subdomain.
example.com.        ALIAS   cname.vercel-dns.com.     # Cloudflare/Netlify/Route53/DNSimple equivalent
www.example.com.    CNAME   cname.vercel-dns.com.

# Good (no flattening available) — hard-code the host's published A/AAAA at the apex.
example.com.        A       76.76.21.21
www.example.com.    CNAME   cname.vercel-dns.com.

Then pick one canonical host and 301 the other to it (apex→www or www→apex — either, just be consistent). Two live origins split your SEO and your cookies. The redirect lives at the host/edge, not in DNS.

Record cookbook (summary)

One example row per type. Edge cases — TXT 255-char chunking, MX priority math, the SPF 10-lookup limit, SRV format, NS/SOA, PTR, DNSSEC — live in references/record-cookbook.md.

TypeUse forExample (name → value)
Aname → IPv4app → 76.76.21.21
AAAAname → IPv6app → 2606:4700::6810
CNAMEsubdomain → another name (never apex)www → cname.vercel-dns.com.
ALIAS/ANAMEapex → another name (flattened to A/AAAA)@ → cname.netlify.app.
MXwhere mail is delivered (priority, lower = first)@ → 10 mail.example.com.
TXTSPF / DKIM / DMARC / domain-verification@ → "v=spf1 include:_spf.google.com ~all"
CAAwhich CA may issue certs@ → 0 issue "letsencrypt.org"
SRVservice discovery (proto/port)_sip._tcp → 10 5 5060 sip.example.com.

The SPF/DKIM/DMARC/MX rows belong here. Whether mail lands — reputation, warmup, inbox placement — is ../email-deliverability/SKILL.md.

TLS / certificates

The 2026 reality: the CA/Browser Forum cut the maximum public-TLS lifetime to 200 days (from 398) on 2026-03-15, dropping to 100 days on 2027-03-15 and 47 days on 2029-03-15; domain-validation reuse is capped the same way (200 → 100 → 10 days). Manual annual certs are dead. Automate renewal or accept guaranteed outages.

Decision: how does the CA prove you control the domain?

ChallengeUse whenCost
HTTP-01Single host, port 80 reachable, no wildcardSimplest; needs inbound :80
DNS-01Wildcard cert, or port 80 closed, or cert issued off-boxNeeds API access to write a _acme-challenge TXT

Rules, each with the failure it prevents:

  • Add a CAA record that allows your CA first. 0 issue "letsencrypt.org". Wildcards need the separate issuewild tag. A CAA that omits your CA makes ACME fail with a CAA error before any cert is issued (RFC 8659).
  • Serve the full chain, not the leaf. A leaf-only config validates in browsers (they cache intermediates) but fails on curl and mobile — the classic "works on my machine" TLS bug. Serve fullchain.pem.
  • Use the ACME staging environment to test. Let's Encrypt allows 50 certs per registered domain per rolling 7 days; burning that on retries locks you out for a week. Renewals recognized via ARI (ACME Renewal Info) are exempt from the limit.
  • Prefer platform-managed certs when the host offers them. Vercel/Netlify/Cloudflare provision and renew automatically once the record resolves — don't hand-roll certbot on top.

certbot/acme.sh recipes, wildcard via DNS-01, Cloudflare Full vs Full(strict), and the renewal-automation + ARI detail are in references/tls-and-acme.md.

Show full SKILL.md (381 more words)Show less

Verify it

Query the authoritative answer and the wire, never your local cache.

bash
dig +short app.example.com                      # the resolved record, your resolver's view
dig +trace example.com                          # full delegation chain from the root — spot stale NS
dig @ns1.provider.net example.com A             # ask the authoritative NS directly
dig CAA example.com +short                       # confirm the CA you use is allowed
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null \
  | openssl x509 -noout -subject -issuer -dates  # served chain subject/issuer + validity window
curl -vI https://example.com 2>&1 | grep -Ei 'HTTP/|location|SSL certificate'  # status + redirect + cert verdict

Propagation is governed by TTL, not a fixed 48 hours (RFC 2181). To make a change land fast, lower the record's TTL (e.g. to 300s) before you change it, so resolvers re-query sooner. NS/registrar delegation changes can still lag because of registry/TLD TTLs.

scripts/verify.sh <domain> runs the whole done-check read-only: apex-CNAME check, CAA sanity, chain completeness + expiry, HTTPS reachability, www↔apex canonical. The full dig/openssl/curl playbook and an error → cause → fix table are in references/verify-and-debug.md.

Nameserver cutover (no downtime)

Order matters; each step has a reason.

  1. 24–48h ahead, lower the TTL on every record at the current provider (300s). Resolvers will pick up the new zone quickly when you flip.
  2. Pre-stage every record at the new provider — copy A/AAAA/CNAME/MX/TXT/CAA exactly. A missed MX row = lost mail the moment NS flips.
  3. Flip the NS records at the registrar to the new provider's nameservers. This is the only switch; the zone is already correct on the other side.
  4. Verify authoritatively with dig +trace and dig @<new-ns> until the new NS answer is global. Don't trust your browser.
  5. Once stable, raise TTLs back up (3600–86400s) to cut query load.

Anti-patterns

Anti-patternWhy it bitesDo instead
CNAME at the apexIllegal per spec; kills SOA/NS, MX, and other apex recordsALIAS/flattening or hard A/AAAA at apex
"Wait 48 hours" for propagationPropagation is the TTL; you're just guessingLower TTL before change; verify with dig +trace
Confirming a change in your browserLocal/OS resolver cache lies for the old TTLQuery authoritative NS or @1.1.1.1
Manual yearly cert renewalMax lifetime is 200d now, 47d by 2029 — it will expireACME auto-renew or platform-managed TLS
Issuing certs with no CAA / wrong CAAACME fails with a CAA error before issuanceCAA 0 issue "<your-ca>"; add issuewild for wildcards
Serving the leaf cert onlyBrowsers cache intermediates; curl/mobile breakServe fullchain.pem
Splitting one zone across two providersResolvers answer from whichever NS won; records vanish intermittentlyOne authoritative provider per zone
TTL left at 86400 during migrationOld answer cached for a day after you flipDrop to 300s a day ahead
Testing certs against ACME productionBurns the 50-cert/7-day limit; week-long lockoutUse the staging endpoint first

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/domains-dns of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/record-cookbook.md
  • references/tls-and-acme.md
  • references/verify-and-debug.md
  • scripts/verify.sh

Open the folder on GitHubat commit e3d5b33

Compare with similar skills

Domains DNS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Domains DNS compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Domains DNS this skillericrisco/rsc-harness174—~2.4kAutomated safety check: PassMIT
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
OmniRoute Tunnel CLIdiegosouzapw/OmniRoute74k—~339Automated safety check: PassMIT
OmniRoute Tunnelsdiegosouzapw/OmniRoute74k—~209Automated safety check: PassMIT
Cdn Setupsickn33/agentic-awesome-skills47k2 repos~2.9kAutomated safety check: PassMIT
DNS Managementsickn33/agentic-awesome-skills47k2 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • OmniRoute Tunnel CLI

    diegosouzapw/OmniRoute

    Starts, stops, and inspects ngrok, Cloudflare, or custom tunnel connections from the command line, including auth and reachability.

    74k GitHub stars~339 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • OmniRoute Tunnels

    diegosouzapw/OmniRoute

    Create and manage secure tunnels (ngrok, Cloudflare Tunnel, custom) to expose OmniRoute to the internet or share access with remote agents and CI pipelines.

    74k GitHub stars~209 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Cdn Setup

    sickn33/agentic-awesome-skills

    Configure CDNs for content delivery. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check passed
  • DNS Management

    sickn33/agentic-awesome-skills

    Configure DNS zones and records. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.7k tokens
    DevOps & CloudAuto-check passed
  • Managing DNS

    ancoleman/ai-design-components

    Manage DNS records, TTL strategies, and DNS-as-code automation for infrastructure.

    526 GitHub stars~3.6k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check: notes

More from ericrisco/rsc-harness

All 233 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    174 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    174 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    174 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    174 GitHub stars~3.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    174 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    174 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Domains DNS

What does Domains DNS do?

A skill your agent uses when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and…. Domains DNS is an agent skill from ericrisco/rsc-harness. Use when pointing a domain at a host or fixing broken HTTPS — delegating nameservers, writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows, apex vs www, standing up auto-renewing TLS, and cutting nameservers over without downtime.

When should I use Domains DNS?

Domains DNS fits situations like: pointing a domain at a host; fixing broken HTTPS — delegating nameservers; writing A/AAAA/CNAME/ALIAS/MX/TXT/CAA rows; standing up auto-renewing TLS.

How do I install Domains DNS in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill domains-dns -a claude-code`. Or copy the skill folder (skills/domains-dns in ericrisco/rsc-harness) into .claude/skills/domains-dns in your project. Claude Code loads it when a task matches its description.

How do I install Domains DNS in Codex?

Run `npx skills add ericrisco/rsc-harness --skill domains-dns -a codex`. Or copy the skill folder (skills/domains-dns in ericrisco/rsc-harness) into .agents/skills/domains-dns in your project. Codex loads it when a task matches its description.

Can I use Domains DNS in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill domains-dns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/domains-dns, .gemini/skills/domains-dns, .github/skills/domains-dns and .opencode/skills/domains-dns in your project.

What does Domains DNS need to run?

Going by SKILL.md and its folder, Domains DNS needs a shell for the scripts in its folder and the command-line tools its instructions call (openssl and curl). Our summary lists: A Bash shell.

Does Domains DNS access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Domains DNS safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Domains DNS use?

Domains DNS is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Domains DNS use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Domains DNS?

Skills that share tags, products or a category with Domains DNS: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), OmniRoute Tunnel CLI (diegosouzapw/OmniRoute, 74k stars), OmniRoute Tunnels (diegosouzapw/OmniRoute, 74k stars) and Cdn Setup (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Domains DNS?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 174 GitHub stars. The repository holds 233 skills in this directory. The repository was last updated on October 7, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.